Anonymous
2026-09-07 07:47:50
(36 seconds ago)
COPSLICOM WEBEXPLOIT 176.9.124.116 (static.116.124.9.176.clients.your-server.de)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 07:28:39
(19 minutes ago)
(mod_security) mod_security (id:210492) triggered by 176.9.124.116 (static.116.124.9.176.clients.you ...
show more
(mod_security) mod_security (id:210492) triggered by 176.9.124.116 (static.116.124.9.176.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 03:28:35.771929 2026] [security2:error] [pid 5288:tid 5288] [client 176.9.124.116:42902] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "art.mavikalem.org"] [uri "/wp-config.php.bak"] [unique_id "ap5no9I7T_OEKyV_z3s4TgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Octopuce
2026-09-07 07:21:00
(27 minutes ago)
Aggressive web search of vulnerable pages: /wp-config.php.bak /wp-config.php~ /wp-config.php.save /w ...
show more
Aggressive web search of vulnerable pages: /wp-config.php.bak /wp-config.php~ /wp-config.php.save /wp-config.php.old /wp-config.php.orig /wp-co ...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 06:48:07
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 176.9.124.116 (static.116.124.9.176.clients.you ...
show more
(mod_security) mod_security (id:210492) triggered by 176.9.124.116 (static.116.124.9.176.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 02:48:01.489121 2026] [security2:error] [pid 20217:tid 20217] [client 176.9.124.116:48460] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gasoilliquidsdaily.com"] [uri "/wp-config.php~"] [unique_id "ap5eIV8kitAa2k81mfGbHgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 05:23:14
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 176.9.124.116 (static.116.124.9.176.clients.you ...
show more
(mod_security) mod_security (id:210492) triggered by 176.9.124.116 (static.116.124.9.176.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 01:23:09.338760 2026] [security2:error] [pid 25803:tid 25803] [client 176.9.124.116:37788] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "adlc18.org"] [uri "/wp-config.php.save"] [unique_id "ap5KPUPCGmfoxKtqdDNt1gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 05:06:53
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 176.9.124.116 (static.116.124.9.176.clients.you ...
show more
(mod_security) mod_security (id:210492) triggered by 176.9.124.116 (static.116.124.9.176.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 01:06:46.872315 2026] [security2:error] [pid 2735:tid 2735] [client 176.9.124.116:47606] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lasertherapyoc.com"] [uri "/wp-config.php~"] [unique_id "ap5GZtiT_mfM8FYqCXrkkwAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-07 04:07:09
(3 hours ago)
Abuse detected: rate-limit and/or cross-site thresholds exceeded.
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-07 04:05:31
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 176.9.124.116 (static.116.124.9.176.clients.you ...
show more
(mod_security) mod_security (id:210492) triggered by 176.9.124.116 (static.116.124.9.176.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 00:05:26.134494 2026] [security2:error] [pid 16701:tid 16701] [client 176.9.124.116:36968] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.frelsburg.com.cajunfriedturkey.com"] [uri "/wp-config.php~"] [unique_id "ap44BvePkxYOf288hKslSQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 03:48:37
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 176.9.124.116 (static.116.124.9.176.clients.you ...
show more
(mod_security) mod_security (id:210492) triggered by 176.9.124.116 (static.116.124.9.176.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 23:48:32.601108 2026] [security2:error] [pid 30246:tid 30252] [client 176.9.124.116:59038] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "conservativelabor.com"] [uri "/wp-config.php~"] [unique_id "ap40EJjKcfC1cc0rJ8E4UQAAAEQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TAY
2026-09-07 03:47:50
(4 hours ago)
176.9.124.116 - - [07/Sep/2026:11:47:30 +0800] "GET /wp-config.php~ HTTP/1.1" 404 48441 "-" "Mozilla ...
show more
176.9.124.116 - - [07/Sep/2026:11:47:30 +0800] "GET /wp-config.php~ HTTP/1.1" 404 48441 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
176.9.124.116 - - [07/Sep/2026:11:47:19 +0800] "GET /wp-config.php.bak HTTP/1.1" 404 48441 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
176.9.124.116 - - [07/Sep/2026:11:47:41 +0800] "GET /wp-config.php.save HTTP/1.1" 404 48441 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
176.9.124.116 - - [07/Sep/2026:11:47:42 +0800] "GET /wp-config.php.old HTTP/1.1" 404 48441 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
176.9.124.116 - - [07/Sep/2026:11:47:44 +0800] "GET /wp-config.php.orig HTTP/1.1" 404 48441 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML,
...
show less
Brute-Force
🇫🇷
COMAITE
2026-09-07 03:14:27
(4 hours ago)
Suspicious URL access.
Web App Attack
Anonymous
2026-09-07 02:25:08
(5 hours ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
Anonymous
2026-09-07 01:36:34
(6 hours ago)
[ns31.kdns.gr] httpd-config-scan: sites=www.savouras.gr; logs=/var/log/httpd/access_log,/var/log/htt ...
show more
[ns31.kdns.gr] httpd-config-scan: sites=www.savouras.gr; logs=/var/log/httpd/access_log,/var/log/httpd/domains/savouras.gr.log; samples=/wp-config.php.bak | /wp-config.php~ | /wp-config.php.save
show less
Hacking
Web App Attack
🇸🇪
SkyDancer
2026-09-07 01:22:36
(6 hours ago)
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by Sk ...
show more
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by SkyDancer Ai. EXT-SYS-Vx
show less
Hacking
Brute-Force
SSH
🇷🇺
cnaize
2026-09-07 01:13:38
(6 hours ago)
Malicious activity blocked by Meds firewall
Port Scan